What is a Web Key Directory?

Web Key Directories provide an easy way to discover public keys through HTTPS. They provide an important piece to the infrastructure to improve the user experience for exchanging secure emails and files.

In contrast to the public keyservers a Web Key Directory does not publish mail addresses. And it is an authoritative pubkey source for its domain.

How does it work?

The senders mail client checks a "well known" URL on the domain of the recipient.

If a public key is available for that mail address, will be downloaded via HTTPS.

The downloaded pubkey can now be used without further user interaction.

Such an URL looks like: https://intevation.de/.well-known/openpgpkey/hu/g8td9rsyatrazsoiho37j9n3g5ypp34h for the mail address "aheinecke@intevation.de"

What does it mean for users?

A user just selects the recipients of a message and by default the encryption state of that mail will toggle if all recipients can be found in a Web Key Directory.